WhatsApp on August 25, 2026 replaced the six-digit PIN behind its two-step verification feature with a full alphanumeric password, added caller context for unknown numbers on Android, and disclosed that more than one billion accounts have set up a passkey.

The announcement arrived through the Meta Newsroom under the WhatsApp category, filed against three tags: Data and Privacy, Product News, and WhatsApp. It carries no byline, no named spokesperson, and no rollout schedule. What it carries instead is a change to the credential layer of a messaging service that now doubles as a paid media surface, a customer service channel, and the subject of an active European antitrust remedy.

Three changes were described. Each is small on its own. Together they mark a shift in where WhatsApp places the burden of account integrity, and they land at a moment when account takeover has become an operational problem for the advertising industry rather than a consumer inconvenience.

The PIN becomes a password

Two-step verification on WhatsApp exists to defeat a specific attack: an adversary who has obtained the one-time passcode sent during registration, whether through SIM swap, social engineering, or interception. The feature adds a second secret that the attacker does not hold.

Until the August 25 announcement, that second secret was a six-digit numeric PIN. According to WhatsApp, the company has upgraded it to a full password that is longer, alphanumeric, and capable of containing special characters. The stated purpose is to make the credential harder to guess.

The arithmetic behind that decision is not stated in the announcement, but it is not obscure. A six-digit numeric PIN has one million possible values. A password drawn from mixed-case letters, digits, and punctuation expands that space by orders of magnitude per additional character. Against an attacker who has already cleared the one-time passcode hurdle and is guessing at the second factor, the difference between the two formats is the difference between a search that terminates and one that does not.

What the announcement does not address is migration. There is no statement on whether existing six-digit PINs remain valid, whether users are prompted to upgrade, whether a deadline applies, or whether the change reaches all markets simultaneously. Accounts already carrying a PIN are left in an undefined state by the text as published.

Caller context lands on Android first

The second change concerns inbound calls from numbers not saved in a user's contacts. On Android, WhatsApp now surfaces additional information about the caller before the call is answered: whether the number originates in a different country, and whether the caller shares any groups with the recipient.

Both signals are inferences drawn from metadata rather than message content. Neither requires WhatsApp to inspect the encrypted payload of a conversation, which is consistent with the architecture the company describes. According to WhatsApp, conversations belong only to the participants, and end-to-end encryption by default is the reason the company frames account security as a separate layer of work.

The rationale offered is behavioural. According to WhatsApp, "Scammers rely on urgency," and the added context is intended to slow the decision to answer.

iOS is not mentioned. The announcement specifies Android and stops there, with no parity date and no explanation for the platform split. That asymmetry has precedent in recent WhatsApp releases, several of which have shipped without a market sequence or a distinction between the European Region and other territories.

Passkeys reach one billion accounts

The third disclosure is the only one carrying a number. According to WhatsApp, more than one billion people have set up a passkey, a credential that allows sign-in through a fingerprint, a face scan, or a device screen lock rather than a code or PIN. The company describes it as the fastest and most secure way to complete verification.

Alongside the figure, WhatsApp added a capability: accounts can now hold more than one passkey, which matters for people running both Android and iOS devices. The setup path is Settings, then Account, then Passkeys.

One billion is a substantial share of a user base that stood at three billion monthly active users as of May 2025, the figure cited in Meta's own regulatory materials when WhatsApp opened third-party messaging in Europe under the Digital Markets Act. It is also a figure without a stated baseline. The announcement gives no prior total, no growth rate, and no time window, so the adoption curve cannot be reconstructed from the text.

The credential itself is not new to WhatsApp, and passkeys are not new to Meta's competitors. What has changed over the past eighteen months is the migration of the same mechanism from consumer login into advertising infrastructure.

The same credential now gates ad accounts

Passkey adoption on a messaging app would be a consumer story if the advertising platforms had not made the identical move on their own account systems.

Google Ads began requiring passkeys for sensitive account actions from July 15, 2026, covering account linking updates and user access changes specifically. The requirement surfaced at the developer layer through a boolean field named passkey_enabled in Google Ads API v24.1, released May 13, 2026, allowing integrations to check enrolment state before attempting a sensitive operation. A further deadline followed: from August 5, 2026, generating new OAuth 2.0 refresh tokens through the Google Ads API authentication workflow requires a passkey, with a seven-day device trust period that agencies rotating staff onto accounts have flagged as an operational trap.

The structural consequence for agencies is that passkeys cannot be shared. Organisations running shared credentials across a team must assign individual accounts to each person performing sensitive operations, a change that reaches into how account access is administered rather than merely how it is authenticated.

WhatsApp's consumer-side figure and the ad platforms' enforcement deadlines are separate programmes with separate timelines. They point the same direction. The password, as a transferable secret, is being retired across both sides of the platform economy, and the replacement is bound to a physical device.

Why a security post matters to media buyers

WhatsApp is no longer a purely organic channel. Meta began placing advertisements on WhatsApp Status on June 16, 2025, targeting the roughly 1.5 billion people who open the Updates tab daily and drawing targeting signals from connected Instagram and Facebook accounts. Meta's third Digital Markets Act compliance report, filed March 6, 2026, confirmed that Channels and Status advertising was being prepared for the European Union. Advertisers gained a WhatsApp filter in the Meta Ads Library in December 2025, and Marketing API v26.0 expanded the placement further, requiring third-party callers to include a wamo_whatsapp_identity_spec field in creatives intended for Status delivery.

The business layer moved in parallel. Meta launched Meta Business Agent globally on June 3, 2026, putting AI customer service across WhatsApp, Messenger, and Instagram, and the WhatsApp Business Calling API arrived on July 1, 2025 to fold voice into existing message threads. Onboarding for Click-to-WhatsApp campaigns was consolidated in embedded signup v4, which sets an October 15, 2026 deprecation deadline for the two prior versions.

Every one of those commercial surfaces sits on top of a consumer account. A compromised account is a compromised endpoint for a conversational campaign, a hijacked identity in a Click-to-WhatsApp funnel, and an attack surface for the scam operations Meta has spent two years trying to remove from its own inventory.

The fraud economy the changes sit against

The commercial context for account hardening at Meta is unusually well documented, largely because much of it has been documented against the company's wishes.

Internal documents reviewed by Reuters in November 2025 indicated Meta projected roughly 10% of its 2024 revenue from advertisements for scams and banned goods, and estimated that its platforms showed users around 15 billion higher-risk scam advertisements a day. The Consumer Federation of America filed a class action in the Superior Court of the District of Columbia on April 21, 2026, citing a 2023 internal document showing approximately 100,000 valid weekly reports of fraudsters messaging Facebook and Instagram users.

Meta's own disclosures run alongside. At the Global Anti-Scam Summit in Washington on December 3, 2025, the company reported removing more than 134 million scam advertisements during 2025 and disrupting nearly 12 million accounts across Facebook, Instagram, and WhatsApp in the first half of 2025 associated with criminal scam centres. A joint law enforcement operation with the FBI, the Department of Justice Scam Center Strike Force, and the Royal Thai Police Anti-Cyber Scam Center disabled more than 150,000 further accounts.

The economics on the attacker side have moved in the wrong direction. HUMAN Security's Satori threat intelligence team documented a phone-farm scam kit available for 5,000 dollars upfront and 450 dollars a month, against an estimated 27.8 billion dollars in annual romance and pig-butchering scam losses.

Regulators have started writing account security into code. Ofcom's draft scam-ad measures, published in July 2026 against an estimated 200 million pounds in annual UK losses to fraudulent advertising, include measure H3 requiring an account security mechanism on all advertising accounts and measure H4 requiring an account takeover reporting mechanism. The consultation closes on 2 October, with rules expected in 2027.

Consumer-side two-step verification on WhatsApp does not answer any of that directly. It does sit on the same axis: platforms are being pushed, by litigation and by regulators, to raise the cost of holding a stolen identity.

The regulatory frame in Europe

WhatsApp's product cadence in 2026 has run alongside sustained European pressure. The service enabled interoperable third-party messaging with BirdyChat and Haiket on November 14, 2025 under Article 7 obligations. The European Commission issued a Supplementary Statement of Objections on April 15, 2026 in case AT.41034 over Meta's exclusion of rival AI assistants from WhatsApp, then ordered the company on June 9, 2026 to restore free API access for third-party general-purpose assistants under the terms in place before October 15, 2025.

None of that touches account security directly. It shapes the environment in which the announcement was made. Security features that alter authentication flows across the European Economic Area intersect with interoperability obligations, because a third-party client connecting through WhatsApp's server infrastructure inherits whatever credential model the host service defines. The announcement is silent on whether the password upgrade or the multi-passkey capability affects interoperable clients.

What was not published

The gaps in the August 25 post are worth listing, because they determine what can and cannot be assessed.

No rollout dates were given for any of the three changes. No market sequence was published. No distinction was drawn between the European Region and other territories. The caller context feature is specified for Android with no iOS commitment. The passkey figure carries no baseline and no growth period. Migration handling for existing six-digit PINs is not addressed. No security incident, breach, or takeover volume is cited as the motivation.

The post closes with a forward-looking sentence and nothing attached to it: according to WhatsApp, the company will keep building tools that help people stay in control of their accounts.

Timeline

Summary

Who: WhatsApp, the messaging service owned by Meta Platforms, publishing through the Meta Newsroom without a named author. The changes affect consumer account holders, and indirectly the advertisers, agencies, and business messaging operators building on WhatsApp Status advertising, Click-to-WhatsApp campaigns, and the WhatsApp Business Platform.

What: Three account security changes. Two-step verification moves from a six-digit numeric PIN to a full alphanumeric password supporting special characters. Android users receive additional context on calls from numbers not in their contacts, specifically whether the number originates in another country and whether groups are shared. Accounts can hold more than one passkey, useful for people operating both Android and iOS devices, and the company reported that more than one billion people have set up a passkey.

When: August 25, 2026. No rollout dates, market sequences, or migration deadlines were published for any of the three changes.

Where: The Meta Newsroom, filed under the Data and Privacy, Product News, and WhatsApp categories. The caller context feature is specified for Android only. Geographic availability is not stated for any change, and no distinction is drawn between the European Economic Area and other territories.

Why: According to WhatsApp, account security work continues alongside default end-to-end encryption because conversations belong to their participants, and scammers rely on urgency that additional caller context is intended to interrupt. The commercial backdrop is a platform that has been converted into an advertising surface since June 2025, an antitrust remedy in Europe, and a documented fraud economy in which account takeover has become an enforcement subject for regulators in the UK and litigation in the United States.